This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have
This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP hav
This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have alr
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Stat
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Stat
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Co
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certifica
In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision compa
In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lea
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript lite
ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this v
In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that coul
A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style th
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Pow
Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java sc
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker t
Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t
Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3),
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multi
A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1),
Frequently Asked Questions
What is CWE-80?
CWE-80 (CWE-80) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-80?
There are 577 CVE records associated with CWE-80 in our database. Of these, 14 are critical severity, 70 are high severity, and 387 are medium severity.
How can I protect against CWE-80 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-80 using AI-powered security agents.
Detect CWE-80 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-80 vulnerabilities across your infrastructure.
Get Started